Windows 11 KB5124008 Is Breaking Always On VPN Connections


KB5124008 breaks vpn windows 11
Image credit: Microsoft

KB5124008 is causing Always On VPN failures on Windows 11 systems that use certificate-based authentication, according to administrator reports following Microsoft’s September 2026 Patch Tuesday rollout.

The issue can prevent affected PCs from completing the VPN connection, potentially leaving corporate users without remote access. Reports indicate that Windows 11 24H2 and 25H2 clients are affected.

The problem follows Microsoft’s September 2026 Windows 11 Patch Tuesday update and comes alongside separate RDS failures reported on Windows Server.

KB5124008 breaks certificate-based Always On VPN connections

Reports involve Windows 11 devices connecting to Windows Server 2019 systems running Remote Routing and Access Service, or RRAS, together with Network Policy Server.

An administrator reporting the problem on Microsoft Learn said removing KB5124008 and restarting the affected Windows client immediately restores VPN connectivity.

That behavior points to KB5124008 as the trigger rather than a previously working VPN configuration suddenly becoming invalid.

Certificate negotiation may be failing

The regression appears to occur during certificate negotiation as Windows attempts to establish the VPN connection.

An independent advisor suggested that KB5124008 may have introduced a change to the Windows networking stack or IPsec certificate handling.

Microsoft has not confirmed the exact cause, so administrators should treat that explanation as a possible cause rather than a confirmed diagnosis.

Administrators have limited workaround options

Organizations affected by the issue can pause deployment of KB5124008 through WSUS or Intune while waiting for Microsoft to investigate the reports or release a fix.

Administrators who cannot remove the security update because of compliance requirements can also try moving affected VPN profiles to EAP-TLS authentication through Intune.

Uninstalling or delaying KB5124008 carries a significant security trade-off. Microsoft’s September Patch Tuesday release included 966 security fixes, so removing the update could leave systems exposed to vulnerabilities addressed this month.

Microsoft has not yet confirmed the Always On VPN regression or announced a permanent fix.

Via Neowin

More about the topics: KB5124008, microsoft, VPN, Windows 11

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages